
๐ก๏ธ ืืกืืืืช ืืขืจืืืช ืืคืขืื (OS) ืืกืืืื ืืื ืืกืืืืจ โ ืืืคืก ืืคืจื
1) ืืื ืืขืจืืช ืืคืขืื?
ืืขืจืืช ืืคืขืื (OS) ืืื ืฉืืืช ืืชืืื ื ืฉืืื ืืืฉืชืืฉืื/ืืืคืืืงืฆืืืช ืืืื ืืืืืจื. ืืื ืืงืฆื ืืื ืืขืื, ืื ืืืช ืืืืจืื ืืงืืฆืื, ืฉืืืืช ืืืชืงื ืื, ืืืกืคืงืช ืืืฉืง ืขืงืื ืืจื ืงืจืืืืช ืืขืจืืช ืึพShell/GUI ืืื ืฉืชืืื ืืืช ืืจืืฆื ืืืขืืืืช ืืืืืืืืช.
2) ืืืจืืืช ืืืืื ืฉื ืืขืจืืช ืืคืขืื
- ื ืืืื ืชืืืืืื ืึพCPU: ืืฆืืจื/ืกืืื ืชืืืืืื, ืชืืืื ืชืณืจืืื ืขื ืืืืืช.
- ื ืืืื ืืืืจืื: ืืงืฆืืช RAM, ืืืฉืื ืืืืจืื ืืืจืืืืื, ืืืืืคืช ืืืืื.
- ื ืืืื ืืชืงื ืื ืืงืื/ืคืื: ืืคืฉืืช ืืืกืงืื, ืืจืืืกื ืจืฉืช, ืืงืืืืช ืืืืฆืขืืช ืืจืืืืจืื.
- ื ืืืื ืืขืจืืช ืงืืฆืื: ืืจืืื ื ืชืื ืื ืืงืืฆืื/ืกืคืจืืืช ืขื ืืจืฉืืืช.
- ืืืืื ืืืืฉืื ืฉืืืืฉืื: ืืืืื, ืืจืฉืื, ืืืืื, ืืืกืืช.
- ืืืฉืง ืืืฉืชืืฉืื ืืืชืืื ืืช: Shell/GUI ืึพAPI ืฉื ืงืจืืืืช ืืขืจืืช ืืืคืืืงืฆืืืช.
3) ืืจืืืืงืืืจืช OS: Kernel, Shell ืืงืจืืืืช ืืขืจืืช
- Kernel (ืืืื): ืืืืื ืืืืจืฉืืช ืฉืคืืขืืช ืึพKernel Mode, ืืืคืืช ืืชืืืื, ืืืืจืื, ืืจืืืืจืื, ืืขืจืืืช ืงืืฆืื ืึพIPC.
- Shell: ืืืืฉืง ืืืฉืชืืฉ (CLI ืื GUI) ืฉืืคืจืฉ ืคืงืืืืช ืืืจืืฅ ืชืืื ืืืช.
- ืงืจืืืืช ืืขืจืืช (syscalls): ื ืงืืืืช ืื ืืกื ืืืืงืจืืช ืืฉืื ืืฉืชืืฉ ืืฉืืจืืชื ืืืืื (ืืืฉื
open,read,execve,CreateProcessW).
ืกืื ืื ืืช ืืืื ื ืคืืฆืื ืืกืืืืจ:
- Monolithic (ืืืฉื Linux) โ ืจืื ืืฉืืจืืชืื ืืืืื.
- Microkernel โ ืืืืคืื ืฉืืจืืชืื ืืฉืื ืืฉืชืืฉ ืืืืืืืจืืืช.
- Hybrid (ืืืฉื Windows, XNU) โ ืฉืืืื ืฉื ืืฉื ืืื.
4) ืชืืืืืื, ืชืณืจืืื ืืชืืืื CPU
- ืชืืืื (Process): ืชืืื ืืช ืฉืจืฆื ืขื ืืจืื ืืชืืืืช ืืืจืืืืื ืืฉืื.
- ืชืณืจื (Thread): ืืืืืช ืชืืืื ืืชืื ืชืืืื, ืืืืงืช ืืืืจืื.
- ืืชืืื ืื (Schedulers): ืืืืืืื ืื ืจืฅ ืขืืฉืื (FCFS, SJF, Priority, Round-Robin, MLFBQ). ืืืื ื ืงืืืื/ืื-ืงืืืื, ืืืืคืืช ืืงืฉืจ (context switch) ืืจืขืืื ืืืืืช ืืืฆืืขืื ืื ืืชืื ืคืืจื ืื.
5) ื ืืืื ืืืืจืื ืืืืืจืื ืืืจืืืืื
- ืืืืจืื ืืืจืืืืื: ืืขื ืืง ืืื ืชืืืื ืืจืื ืืชืืืืช ืืืื ืืืืื, ืืืืื ืึพRAM ืืืืืกืง (ืืคืืืฃ/Paging).
- ืืืืืจืืชืื ืืืืคืช ืืคืื: (ืืืฉื FIFO, LRU, Optimal) ืืืื ืื ืืืงืืืืช ืืื ืชืงืืจื.
- ืืื ื: (ืืฆืื User/Kernel, ืืจืฉืืืช ืืคืื) ืืื ืขืช ืคืืืขื ืืืืืช ืืื ืชืืืืืื.
6) ืืืกืื, ืืขืจืืืช ืงืืฆืื ืึพI/O
- ืืขืจืืืช ืืคืขืื ืืืฉืคืืช ืืขืจืืืช ืงืืฆืื (ืืืฉื ext4/XFS ืืืื ืืงืก, NTFS/ReFS ืืืืื ืืื) ืขื ืืืึพืืื, ืืจืฉืืืช/ACLs, ืึพJournaling ืืืืกื.
- Block I/O (ืืืกืงืื/SSD) ืืฉืชืืฉ ืืชืืืื ืื; Character I/O (ืืกืืคืื) ืืื ืืจืื.
- ืชืืืื ืืืกืง (SCAN/LOOK) ืืืืคืจืื ื/ืงืืฉืื ื ืืฉืคืจืื ืชืคืืงื.
7) ืชืืืื ืืืชืืื ืืืฆืื ืคืขืืื
ืฉืืืื ืืืคืืกืืื:
- ืงืืฉืืช UEFI/BIOS ืืืฆืขืช ืืชืืื ืืืืจื ืืืืชืจืช Bootloader.
- Bootloader ืืืขื Kernel (ืึพinitramfs) ืืืืืจืื.
- ืืืืื ืืืชืืืช ืชืชึพืืขืจืืืช, ืืขืืืกื Root FS ืืืชืืืื ืชืืืื ืืฉืชืืฉ ืจืืฉืื (
init/systemdืื Windows Session Manager). - ืฉืืจืืชืื ืืื ืื ืืชืืืจืืช/ืกืฉื ืขืืืื.
ืคืขืืืืช ืืฉืชืืฉ ืงืืจืืช ืึพUser Mode; ืืืืช ืืืขืจืืช ืึพKernel Mode.
8) ืืกืืืืช ืืืืื (ืืฉืืื ืืช, ACLs, ืืืื ืืืช)
ืคืจืืืืืืืื ืืฉืืชืคืื:
- ืืืืืืช ืืงืืืฆืืช; ืืจืฉืืืช (rwx, ACLs), ืืขืืืช, ืืืืืืืช ืืจืฉืื.
- ืืืืคืช ืืืื ืืืช (ืืืฉื UAC ืึพGroup Policy ืึพWindows; DAC + MAC ืืื SELinux/AppArmor ืืืื ืืงืก).
- ืืืงืืจืช ืืืืืื (Windows Event Logs, syslog/journald ืืืื ืืงืก).
ืืืืืื ืช ืืืืื: ืขืงืจืื ืืืื ืืืื, ืขืืืื ืื, ืืืืืช ืืืง.
9) ืืืจืืืืืืืฆืื ืืงืื ืืืื ืจืื
- ืืืื ืืช ืืืจืืืืืืืช (VMs): ืืืืืช ืืืืจื ืืืื ืืืจืืฅ ืืกืคืจ OS ืขื ืืืชื ืฉืจืช.
- ืงืื ืืืื ืจืื: (namespaces/cgroups ืืืื ืืงืก) ืืืืืืื ืชืืืืืื ืขื ืืื ืืืชื ืืืืโืืชืืื ืืืืจ ืืฆืคืืคืืช ืืืืื, ืืขืืืื ืืคืจืืืงืฉื ืืืืขืืืืช.
10) ืกืืื OS: ืืกืงืืืค, ืฉืจืชืื ืื ืืื
- ืืกืงืืืค: Windows, macOS, ืืคืฆืืช Linuxโืคืจืืืืงืืืืืืช, ืคืืชืื, ืืืืืื ื.
- ืฉืจืช: Linux/Windows Serverโืฉืืจืืชืื ืืื GUI, ืืืื ืื ืืืฆืืขืื ืืืืืื.
- ื ืืื: Android/iOSโืกื ืืืืงืก ืืืคืืืงืฆืืืช ืืคืจืืืืืืช ืืืืื ื ืืืืืช.
11) Linux ืืขืืืช Windows: ืขืงืจืื ืืช ืืืืื ืืกืืจืฆืื (Hands-On)
ื ืืืื ืืฉืชืืฉืื ืืงืืืฆืืช
- Linux:
useradd,groupadd,passwd -l, ืงืืฆืื/etc/passwd,/etc/shadow. - Windows:
net user,net localgroup, ืึพMMC ืฉื Local Users & Groups.
ืืืืืืช ืืขืืืื ืื
- Linux: ืื ืืื ืืืืืืช
apt,dnf,yum,apk. - Windows: Winget/Chocolatey; ืฉืืจืืช Windows Update (
wuauserv).
ืฉืืจืืชืื ืืืชืืื
- Linux:
systemctl enable|start <service>(systemd) ืืservice(SysV). - Windows: Service Control Manager (
sc config/start/stop), ืึพServices.msc.
ืงืืฆืื ืืืจืฉืืืช
- Linux:
chmod,chown, umask; ืืขืจืืืช ืงืืฆืื ext4/XFS. - Windows: ืืจืฉืืืช NTFS (GUI ืื
icacls), ืืืจืฉื ืืืืืืืื ื.
ืืืืื
- Linux:
/var/log/*,journalctl; logrotate ืืกืืื ืืืืื ืืืืืกื. - Windows: Event Viewer โ ืืืื Application/Security/System; ืืืื ืืืช ืฉืืืจืช ืืืืื ืึพGroup Policy ืื ืืงืื ืกืื.
12) ืืืืื, ื ืืืืจ ืืืจืืืฉืืืื ื
- Linux:
journalctl -u <svc>,dmesg,top/htop,ss -tulpn,lsof,strace. - Windows: ืืกื ื ืื ืึพEvent Viewer, Resource Monitor, Process Explorer,
Get-WinEvent,Get-Process,netstat, ืืื Sysinternals. - ืืฆืขื ืจืืืฆืืืช ืืืืื, ืจืืื ืืืืื (syslog โ SIEM), ืืงืืขื ืืืื ืืืช ืฉืืืจื ืืืืฉื. logrotate ืืื ืืืื ืืกืื ืืจืื ืืืื ืืงืก ืืืืืืืฆืืืช ืจืืืฆืื.
13) ืฆืณืงึพืืืกื ืืงืฉืื (Linux & Windows)
Linux
- ืืืืื ืื ืืกืช root ืึพSSH (
PermitRootLogin no), ืืขืืคืช ืืคืชืืืช. - ืขืืืื ืฉืืจืชื; ืืื ืืืื ืืืืืืช; ืืืืชึพืืฉ (
ufw/nftables). - ืืจืฉืืืช ืงืืฆืื ืจืืืฉืื (ืืืฉื
/etc/shadowืืจืฉืื 640, ืืขืืืชroot:shadow). - ืืืืจืช logrotate ืืืืืื ืืจืืืืื; ื ืืืืจ ืืฉืื ืืชืืืจืืช.
Windows
- ืืืืคืช NLA ืึพRDP; ืืืืื Guest; ืืืื ืืืช ื ืขืืืืช ืืืงื.
- ืฉืืจืืช Windows Update ืคืขืื; Defender + SmartScreen ืืืคืขืืื.
- ืฆืืฆืื ืฉืืืืฉ ืืื ืืื ืืขืจืืช ืืงืืืืื; ืขืงืจืื ืืืื ืืืื; AppLocker/WDAC.
- ืงืืืขืช ืฉืืืจืช ืืืืื ืืืืจืื ืึพSIEM.
14) ืฉืืืืช ื ืคืืฆืืช ืืจืืืื ืืช/ืืืื ืื (ืขื ืชืฉืืืืช)
- ืืื ืืขืจืืช ืืคืขืื? ืฉืืืช ืชืืืื ืืื ืืืฉืชืืฉ/ืืคืืืงืฆืืืช ืืืืืจื; ืื ืืืช ืืฉืืืื ืืืกืคืงืช ืฉืืจืืชืื.
- Process ืืขืืืช Thread? ืืชืืืื ืืจืื ืืชืืืืช ืืฉืื; ืชืณืจืืื ืืฉืชืคืื ืืช ืืืืืจืื ืื ืงืืืช ืืชืืืื.
- ืืื ืืืืจืื ืืืจืืืืื? ืืคืฉืื ืฉื ืืชื ืช ืืชืืืืืื ืืจืืื ืืชืืืืช ืืืืืืื ืืขืืจืช ืืคืืืฃ ืืืืกืง.
- Kernel ืืขืืืช Shell? Kernel = ืืืื ืคืจืืืืืืืช; Shell = ืืืฉืง ืืฉืชืืฉ (CLI/GUI) ืืืืืจ ืขื ืืืืื ืืงืจืืืืช ืืขืจืืช.
- Monolithic ืืขืืืช Microkernel? ืืื ืืืืืโืจืื ืืฉืืจืืชืื ืืืืื; ืืืงืจืโืืืื ืืฆืืืฆืืช, ืฉืืจืืชืื ืืฉืื ืืฉืชืืฉ.
15) ืืื ืึพืืขืืืืช: ื ืกื ืขืืฉืื
ืืจืืฆื ืืกืืืืช VM/ืงืื ืืืื ืจ ืืึพืคืขืืืช.
Linux
# 1) ืืฉืชืืฉืื ืืงืืืฆืืช
sudo groupadd secops && sudo useradd -m -g secops -s /usr/sbin/nologin secops && sudo passwd -l secops
# 2) ืืืืืืช (Debian/Ubuntu)
sudo apt-get update -y && sudo apt-get install -y htop && htop --version && sudo apt-get remove -y htop
# 3) ืฉืืจืืชืื (systemd)
sudo systemctl enable --now cron || echo "Not available here"
# 4) ืจืืืฆืืืช ืืืืื
cat | sudo tee /etc/logrotate.d/custom <<'EOF'
/var/log/custom.log {
weekly
rotate 4
compress
missingok
notifempty
create 0640 root adm
}
EOF
sudo touch /var/log/custom.log && sudo chown root:adm /var/log/custom.log && sudo chmod 0640 /var/log/custom.log
# 5) ืืงืฉืืช SSH
sudo sed -i 's/^#\?PermitRootLogin.*/PermitRootLogin no/' /etc/ssh/sshd_config && sudo systemctl restart ssh || true
Windows (PowerShell ืืื ืื)
# 1) ืืฉืชืืฉืื ืืงืืืฆืืช
net user secops /add /y
net localgroup "Users" secops /add
# 2) ืืืืืืช ืืขืืจืช winget (ืื Chocolatey ืื ืงืืื)
winget install --id=7zip.7zip -e; winget uninstall --id=7zip.7zip -e
# 3) ืฉืืจืืชืื
sc config wuauserv start= auto
sc start wuauserv
# 4) ืฉืืืจืช ืืืืื (ืืืืื: Application ื-64MB)
wevtutil sl Application /ms:67108864
# 5) RDP + NLA ืืืืืฅ (Group Policy / System Properties > Remote)
16) ืืืืื ืืื ืืื
- ACL: ืจืฉืืืืช ืืงืจืช ืืืฉื โ ืืจืฉืืืช ืืจื ืืืจืืืช ืขื ืืืืืืงืืื.
- Context Switch: ืฉืืืจืช/ืฉืืืืจ ืืฆื CPU ืืืขืืจ ืืื ืชืณืจืืื.
- Journaling FS: ืืขืจืืช ืงืืฆืื ืฉืจืืฉืืช ืฉืื ืืืื ืืืืื ืืฉืจืืืืช ืืงืจืืกื.
- Kernel/User Mode: ืจืืืช ืืจืฉืื ืฉื ืึพCPU ืืงืืืขืืช ืคืขืืืืช ืืืชืจืืช.
- Paging (ืืคืืืฃ): ืืขืืจืช ืืคืื ืืื RAM ืืืืกืง.
- Preemption (ืงืืืื): ืืืชืืื ืขืืฆืจ ืชืณืจื ืจืฅ ืืื ืืืจืืฅ ืืืจ.
- System Call (ืงืจืืืช ืืขืจืืช): ืืืื ืึพAPI ืืฉืื ืืฉืชืืฉ ืืฉืืจืืชื ืืืืื.
17) ืืืคืื ืึพSEO ืืคืจืกืื ืืืืื Cyber8200
- ืฉืืื ืืืืืช ืืคืชื ืืืืชืจืืช H1/H2: โOperating System Basicsโ, โOS for Cybersecurityโ, โLinux vs Windows administrationโ.
- ืืืกืืคื ืงืืฉืืจืื ืคื ืืืืื ืืคืืกืืื ืขื Linux CLI, Windows Registry, SIEM/Logging, ืึพThreat Hunting.
- ืกืคืงื Cheat Sheet ืืืืจืื ืึพืกืงืจืืคืื ืืขืืื ืืืืืืช ืืื ืืฉืืืื ืืงืืฉืืจืื ื ืื ืกืื.
- ืืืกืืคื ืืจืงืจ JSON-LD (FAQPage) ืืฉืืืืช ืืชืฉืืืืช ืืื ืืฉืคืจ ืชืืฆืืืช ืขืฉืืจืืช.
ืงื ืืช ืงืจืืืจืช ืืกืืืืจ ืฉืื ืืฉืื ืืื
ืื ืืฆืืชื ืืช ืืชืืื ืืื ืืขื ืขืจื, ืชืืจื ืืขืฆืืื ืื ืชืืืื ืืืฉืื ืขื ืชืืื ืืช ืืืืฉืจื ืืืงืืคื ืืืืืืืืกืืืช ืฉืื ื ืืช 47 ืฉืืืขืืช. ืืฆืืจืคื ืืืืชืจ ื-1,200 ืกืืืื ืืื ืฉืฉืื ื ืืช ืืงืจืืืจื ืฉืืื ืืขืืจืช ืืื ืืงืืช ืืืืื 8200.
